Top
Best
New

Posted by adletbalzhanov 9 hours ago

Shopify replaced Redis with MySQL for inventory reservations–and it scaled(shopify.engineering)
176 points | 98 comments
manbash 6 hours ago|
> Instead of one row per item with a quantity column, we use one row per sellable unit. An item with 10 units has 10 rows.

> But one row per unit for all inventory would break down at scale—an item with 50,000 units across 10 locations would mean 500,000 rows, and the reserve query would slow as it scans through them. Instead, we maintain a bounded pool of available rows, capped at 1,000 per item/location combination. Reservations consume rows from this pool; a replenishment process refills it from the inventory ledger.

Shouldn't I feel uncomfortable with such approach? It seems to create a backoff (pool) for lowering the chance of having a synchronization issue.

esjeon 2 hours ago||
I would call this one-row-per-contract-type, and this is the most general model for the problem (e.g. the model cannot be further broken down into finer level), thus, the most scalable model given storage is dirt cheap.
sandeepkd 5 hours ago|||
Comes down to type of items, when you have physical inventory the number is limited so more manageable and interestingly enough the problem only applies to physical inventory.

You are just spending some more disk space to avoid synchronization issues. Denormalization for performance is a really common pattern, just that people do not start with it in the first place itself

bijowo1676 4 hours ago|||
you should, their design is not the best. There is middle ground between "one row per SKU" and "1000 rows per SKU".

Its called one row per shopping cart*SKU combo.

if two people order 100 and 500 items of the same SKU, respectively, the table should have only two rows: for order1 and order2. Not 600 rows.

jakewins 3 hours ago||
Can you explain how that works? With the row-per-item I can see how you’d use locking primitives etc easily to deal with multiple concurrent shopping carts claiming available inventory.. but how does your solution solve contention? There’d need to be some “number of items in inventory” row, wouldn’t there be contention on that?

The point of one row per item is that thousands of concurrent shoppers don’t need to block each other as they can each claim as many free rows as they need for themselves?

sroussey 56 minutes ago|||
One other advantage is item serial numbers. Or something else that makes an item that seems the same but actually be unique (perhaps the warehouse it’s in?)
bijowo1676 3 hours ago|||
explained below in https://news.ycombinator.com/item?id=49228432
jbird99 6 hours ago|||
I guess it depends on how the replenishment process works. Unless you're ordering over 1000 of an item, I doubt it would be a problem.
bijowo1676 4 hours ago||
replenishment is an unnecessary cludge that only exists due to poor design. an "algorithmical smell" if you wish
jghn 4 hours ago|||
Depends on the scale. Most companies don't approach the scale where this matters.
dbbk 1 hour ago||
I'm familiar with the reserved row approach (I use SELECT FOR UPDATE SKIP LOCKED) and yeah this replenishing idea terrifies me.
isignal 6 hours ago||
It seems there could be a simpler solution.

1. Deduct the reservation from the inventory when the user starts to order, but in the same txn also maintain a separate row for the in progress order flow. 2. If the order flow is aborted or times out have a background process that returns these to the inventory.

That seems simpler than this approach and involves no locking. Though their presented approach is also reasonable, there must be some reason not to choose a simpler flow. It is not that difficult to have a gc service that scales, but may be they didn't want to separate that.

firasd 5 hours ago||
My understanding is: your proposal is not very different from what Shopify is doing except they are tracking 'reserved units' (one per row) and you are proposing tracking 'orders' as the temporary state to then reconcile back with inventory quantities.
isignal 5 hours ago||
Yes, at a high level. It doesn't rely on skip locked, which is not cheap at DB level. DB has to still typically run query and keep going until it finds an unlocked item. Deducting and checking inventory counts are simpler ops inside the DB.
treis 4 hours ago||
This seems like what triggers are for and how we do similar type things. Update trigger on order does select for update on the inventory and increases/decreases it as appropriate.

I don't think you really need that even. An indexed lookup is fast and you don't need to store a computed quantity generally.

stillpointlab 4 hours ago|||
I was investigating Durable Objects (DO) and had Fable walk me through where in my app they might be appropriate. One place had a dependency with billing (where I use a transaction now) and the proposed re-work to allow for concurrent editing with DO looked very much like this, reservations with idempotency keys. And if you add hierarchical allotments then it scales pretty well.

I disagree with the other posters about the bg process, if you have any bg processing already you should be able to handle the few edge cases without too much trouble.

sandeepkd 5 hours ago|||
The moment you added a background process you just replaced the complexity.

1. Backgrounds process can back up

2. They need context of the user and need to switch context per user

3. What if they fail, you create some DLQ or another process to handle the failure

4. Who looks on those failure and how do they act

TLDR; there is always a cost

0x696C6961 5 hours ago||
The design in the shoppify post already had a background process for the item replenishment.
soontimes 5 hours ago|||
Can you clarify why this involves no locking? There can still be 2 actors fighting for the same row.
isignal 5 hours ago||
Two concurrent deductions of inventory do contend but only during the actual DB update. That is just normal DB locking for SQL isolation levels. The blog refers to explicit locking by the app, which is where skip locked comes in.
soontimes 4 hours ago||
Yes, the point is to spread contention across multiple rows. They also mention this in the beginning of the article
vxxzy 5 hours ago||
now you have two problems. what happens when your reservation system backs up?
dbbk 1 hour ago|||
You don't sell stuff I guess
sieabahlpark 5 hours ago|||
[dead]
bijowo1676 4 hours ago||
not the best design to have 1000 rows for each shop*SKU combination. If a candidate proposed this solution during Shopify's System Design interview, i doubt he would be vetted for Senior+ position.

Instead of having 1000 rows per shop*SKU, why not just have one row per shopping cart*SKU?

That way a single row would represent a single cart, and will hold info of multiple items of the same SKU.

No need a cludge with 1000 rows limit and replenishment process. Instead of dealing with N rows, you always deal with a single row.

idoubtit 1 hour ago||
> not the best design [...]

So those engineers at Shopify worked hard for months on a more performant system, but they missed the obvious structure? They chose a complex denormalization for no good reason?

It may be true, but I think it's presumptuous to belittle their work when we have only partial information. My guess is that they had good reasons to think that the more obvious ways would not scale.

And from reading your comments in this thread, I believe your structure would fail at their scale. A SQL query that uses 2 sub-queries with "group by" is probably too heavy. From the post, at peaks there would be millions of active shopping carts.

BTW, I suspect most orders are just for 1 or 2 of each item, so the denormalization is not as heavy as it seems.

post_below 1 hour ago|||
You might not have noticed that essentially the entire blog post was AI written.

There's even this bit where they discover a remarkable trick:

> Each round trip to the database has a cost. For carts with multiple line items, we batch reservation queries using UNION ALL so we fetch all needed units in one round trip

Insights like that really don't read like senior level output, and of course, it's LLM output. I'm not sure it's presumptuous to question it.

bijowo1676 1 hour ago|||
i also work in big tech and know that a lot of bullshit design creeps into system design and prod, because everyone is overworked, overstressed, wants to just get things done for the quarterly performance review as to not get shitcanned with severance

re concurrency, it is not a big issue at all. stock exchanges deal with HFT traders and can easily deal with concurrency of orders. Same can be implemented with shopify, but I doubt they face the same level of concurrency as stock exchange anywhere near

atomicnumber3 3 hours ago|||
I have never worked anywhere where describing how their system actually works would pass the company's own system design interview
matwood 31 minutes ago|||
Others are almost never as dumb as you hoped, and you’re rarely ever as smart as you think.
soontimes 4 hours ago|||
> Instead of having 1000 rows per shopSKU, why not just have one row per shopping cartSKU?

At what point that row is inserted?

bijowo1676 4 hours ago||
per my reading of the article, the protection is only needed for a few seconds, while payment is being processed by the payment system.

so the row is inserted when Payment is initiated, and row is deleted when Payment succeeds

  What is oversell protection?
  Reserve: When payment starts, we mark items as reserved (a short hold, e.g. several minutes).
  Claim: When payment succeeds, we permanently deduct quantity from the inventory ledger (source of truth).

but that system could be easily improved to reserve item when user Adds item to a cart, to prevent scenario when user adds item to a cart, goes through checkout, and after initiating payment gets "soldout error":

  1. Let user add item to a cart by default (happy path)
  2. Initiate async check in the background for SKU and quantity
  2a. The check sums up rows for all SKUs and compares to Inventory table (very cheap check since its done to only active shopping carts)
  3. After few seconds the check comes back, and we let user know that item is soldout, before/the moment user goes to Checkout.
soontimes 4 hours ago||
Ok, but before inserting you must ensure that inventory is not depleted, which means you need to know the count and you need to lock the row. So you still have contention on that item. Them having a 1k buffer allows not to take a lock on a single row every time, and only do it when buffer is empty
bijowo1676 3 hours ago||
there is no need to lock the row, since you a dealing with a shopping cart, not individual item piece. when you run aggregate functions, lock is no needed, it is actually better to run it with SET TRANSACTION ISOLATION LEVEL READ UNCOMMITTED; for aggregation

the check for oversold items is extremely cheap:

  with current_order as (
    select $SKU1, $q2 as quantity
    union
    select $SKU2, $q2 as quantity
  ),
  with carts as (
    select sku, sum(quantity) as reserved
    from active_carts
    group by sku
  ),
  with warehouse as (
    select sku, available_units
    from inventory
    group by sku
  )
  select * from current_order
  inner join carts using (sku)
  inner join warehouse using (sku)
  where warehouse.available_units - carts.reserved < current_order.quantity
assuming there are indexes on sku field in both, results in efficient index seek and agg over 2 tables
soontimes 3 hours ago|||
I don’t understand how this should prevent oversold. You have a check that reports empty or oversold inventory. But how does that check prevent 2 concurrent actors fighting for the last item from inserting 2 rows?
bijowo1676 3 hours ago||
how does current design resolve concurrent actors fighting for the last item ?

there is ultimately needs to be some global mechanism resolving this conflict. Currently it is an order in which db engine processes transactions by locking rows for a transaction, whoever got the first lock, wins the last remaining items.

my design is the same, except it does not need this dance with moving rows between tables, locking them, and the cludge with replenishment process.

in the simplest form, run the sum() over active non-finished orders and compare to inventory. you get the same result: whoever got the first to run sum() and get positive answer will get the last remaining items.

but the problem as formulated, imho, is not even correctly defined.

Shopify incorrectly formulated the very problem they are trying to solve.

Trying to solve it at the payment time is too late, its better to resolve it earlier, before the checkout.

the "PAY" button should only do one thing: deduct money from cc and that's it. Resolving inventory availability must be solved way earlier, the moment user clicks Checkout, not when user clicks Pay.

So ideally, the error for oversold items should be shown to a user when he clicks Checkout, not when he click PAY

admax88qqq 2 hours ago|||
> Shopify incorrectly formulated the very problem they are trying to solve.

That’s a bold overconfident statement. Cart abandonment is real. People never clear their carts they just walk away

Shopify purposefully chooses to do it at payment time because doing it earlier results in lost sales as people “reserve” items and then walk away causing other to see out of stock and then also walk away

Whoever puts up the money first gets the item

That’s the design constraint they chose you can’t just say “their solution is wrong because they solved the wrong problem”. Each design is a different user experience and I think it’s safe to say they chose which experience they want consciously.

bijowo1676 1 hour ago||
that's why I mentioned active carts in my post, there are ways to define active cart to get rid of abandoned carts ( ignore carts where last user action was > N seconds ago).

Ok, let's accept the design goal that whoever paid first wins. You can use the same metric (how many milliseconds ago did user click PAY) and impose a global monotonic non-decreasing counter to distribute the scarce inventory. This is how order matching engines work at stock exchanges with HFT orders (FIFO logic).

the goal is to know with 100% certainty, before sending payment request to payment processor, who will have item and who won't, and you dont need to move mountains of rows for that.

the payment processor should be just a binary answer: payment succeeded or not, but currently it combines Inventory availability check & payment processing, which is the root cause of confusion. For clarity it is better to make that stage of order processing an explicit separage stage, instead of coupling it with payment stage.

some stores split payment into two stages: Payment and Final order confirmation. at the Payment stage you can pre-authorize money at cc and do inventory availability, and at final confirmation you capture $$

hanikesn 57 minutes ago||
Most payment methods in the world don't support separate authorization and capture.
bijowo1676 44 minutes ago|||
i dont know about the world, by authorize.net and Stripe, which work globally and work with global credit cards, they do support separate authorize and separate capture, which seems to be part of PCI standard

https://docs.stripe.com/payments/place-a-hold-on-a-payment-m...

https://support.authorize.net/knowledgebase/Knowledgearticle...

neerajsi 2 hours ago||||
Clearly this is for high concurrency cases where there are many people racing to get all the available items. It's not clear that it's in shopifys or the sellers interest to let items get sequestered in people's shopping carts, which is a spot where there isn't a strong commitment to complete the purchase. At payment time, you can be more assured that the item will actually be purchased.

Still I think their solution is a bit weird. I'd want to commit the reservation transaction with inventory decrement along with a payment key and then use a different transaction to drop the reservation when the transaction completes. If the transaction does not complete in a timely manner you probably need to query external systems anyway to resolve whether the payment actually occurred or not.

They talk about lock contention in this case, but I also wonder about latch contention since these rows are adjacent. If it's a small transaction that's not interactive, does mysql resolve it with just the latches on the needed tables?

soontimes 3 hours ago|||
> how does current design resolve concurrent actors fighting for the last item ?

It resolves with skip locked. Assuming we have only 1 item left. First query scans the buffer table, locks as many rows as needed (1 in our case), and moves rows to another table. Second query scans the table, finds no rows (even if first one hasn’t finished yet, the row is locked and ignored), checks if it can increase buffer, finds out that it’s fully sold and aborts. Db guarantees that you can’t oversold.

> my design is the same, except it does not need this dance with moving rows between tables, locking them, and the cludge with replenishment process.

I can’t evaluate whether it’s the same or not, because you still haven’t clarified when exactly you’re going to insert the row. In the article they’re inserting in the same transaction. Would you also do it in the transaction? Because if you’ll introduce a separate global mechanism to resolve conflicts, on a high level it would be the same as their approach with redis (you need to have 2 systems)

EDIT: wording

bijowo1676 2 hours ago|||
think about for a moment what that skip locked actually means, all these 1000 rows per SKU are logically equivalent to a Inventory table with a single row where available_units=1000 per SKU.

now let's think again, do we need to lock 900 rows to place order on 900 items? or can we insert a single row where order_quantity=900 ?

shopify's design relies on DB to lock rows for transaction as a way to "decrement the counter" of available units. What I am suggesting, is you can just decrement counter by updating a single row, no need to lock 900 rows. Shopify moved from one extreme (single global variable in redis) to another extreme (1000 rows in db) and forgot about the middle ground.

The dance with moving rows per each item between tables is completely unnecessary, it's like counting numbers one by one in a for loop, when you can just substract number directly.

if I were to solve the problem, I would have solved it differently, at the Checkout state, before user clicks PAY. This removes the race condition at the user UI level, before any request lands in backend/db:

  1. Have a table with active shopping carts (cart_id, cart_status, sku, quantity)
  2. when cart_status changes to 'Checkout' run inventory availability check
  3. If inventory availability check fails, show error to user (before he clicks Pay) and suggest replacement items.
  4. If inventory availability succeeds, proceed to charge cc
availability check is the SQL above: inventory-sum(active_carts.quantity)-current_order must be > 0
pas 2 hours ago||
assuming their "reserve item" function is just "update the table set N rows to reserved=true where reserved==false"

more transactions can commit at the same time, but with one counter they would conflict (as it did in the Redis case)

they should use CRDT (and trying to model that with this 1000 row workspace, no?)

still, eventually at some point they need to do the math

Godsend69 2 hours ago|||
[dead]
edoceo 2 hours ago|||
Thanks! I don't uSe 'with' enough
raverbashing 1 hour ago||
And that's why these interviews can be stupid, you can mention the real solution and interviewers might reject because it's not the textbook solution

But the real world is different

REPLicated2 31 minutes ago||
> 3. Consistent lock ordering: avoiding deadlocks

This section is badly written. For example, it refers to different table names than those previously introduced.

The slop shows. While I appreciate the post, I wonder why they didn't bother using an LLM in a way that would at least ensure internal consistency.

zhivota 6 hours ago||
"But the hardest lesson wasn't about database design. It was discovering that the real bottleneck wasn’t what we were observing and measuring."
Horffupolde 6 hours ago||
But was it load bearing?
CoastalCoder 6 hours ago|||
Even better.

It's web-scale.

HatchedLake721 44 minutes ago||||
It needs a ledger
ares623 4 hours ago|||
load = bearing

gun = smoking

insight = key

gap = closed

summary = executived

KingMob 4 hours ago||||
belt = suspended
jtbaker 3 hours ago||
boot = strapped
tweakimp 1 hour ago||
Until now I thought it was boots-trapped. I am not a native speaker :)
berge 3 hours ago|||
[dead]
paytonjjones 5 hours ago||
It's honestly weird Claude converges on this language because it's incredibly wordy and hard to parse.

One would think semantic density would win out in training.

true_religion 3 hours ago|||
Why? This is a common transition that people use in speech and text.

Close out previous paragraph. Segue to completely different topic.

How else are you supposed to go on a tangent?

sroussey 51 minutes ago||||
Each version minor version of Claude has its own preferences for vocabulary.
peyton 5 hours ago||||
Who knows. I wish ant harshly penalized speaking litotically because it’s essentially reward hacking as it can often be read multiple ways.

It’s also annoying as a human because Claude et al rate their own writing very highly, putting human<>LLM interactions at a disadvantage to human->LLM<>LLM interactions.

Jolter 55 minutes ago||
Thanks for teaching me the word ”litotically”!
jasonlotito 5 hours ago|||
[flagged]
nozzlegear 4 hours ago|||
It's not hard to parse, but it's a dense pair of sentences that say nothing. It just pads the length of the article and gives readers mental fatigue trying to read between the lines to figure out what the point is.
CoolestBeans 4 hours ago||||
I actually don't think this article was LLM generated but these two sentences suck. I think they were moved from another part of the article without being modified.

First, "the hardest lesson". What lesson? It is out of context. Nobody was talking about lessons before this.

Second, "the bottleneck wasn't what we were measuring and observing". Of course the bottleneck itself wasn't that. They couldn't discover what the bottleneck was using the information in their measurements and observations.

It is a clunky and frankly incorrect passage in an otherwise well written article.

ares623 3 hours ago|||
Sure, it's not technically hard to read.

But it suuucks, making it hard to read, the same way (some) fast/junk food is hard to swallow.

They have access to a trillion dollar writing machine god, and they choose to publish that.

mrloopex 3 hours ago||
This is absolutely fascinating. I enjoy real life stories like this. I went to a Node meetup in 2013 when Target had just switched to Node from PHP and it was a similar experience to see their metrics and hear their strategy.
firasd 5 hours ago||
Makes sense... if you are counting something in MySQL and now your counter is in Redis that's already strange

But I guess the point is that even in the MySQL scenario the 'reserved_quantities' is almost like a temporary table so either way is not the 'Real' inventory

srcreigh 5 hours ago||
It’s fascinating that in order to do this, they had to remove 50% of reads and 33% of transactions from the main DB.
nurettin 1 hour ago||
At that revenue, why not make your own filesystem, database and index structure? There is no way mysql is the best possible software for this use case. Why stop innovation and hand everything over to ops?
znpy 1 hour ago|
Most likely? Time.

Using off the shelf software means you mostly design how to plumb things together and how to make them correct , safe and scalable.

The things you mention, on the other hand, carry the same requirements but are also much complex to develop AND to maintain.

jbird99 6 hours ago|
The lengths companies will go to avoid running different pieces of software...
matwood 27 minutes ago||
Most companies would be best served picking MySQL or PG and only adding something else if absolutely necessary. Every piece of software added increases complexity.
anonymars 6 hours ago|||
It can be easier and cheaper to solve problems via technology changes than operations and people

Now you only need MySQL expertise and maintenance rather than Redis and MySQL

kirici 39 minutes ago|||
The default should be that every additional piece needs to be justified
More comments...